Description
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT AUTHORITY\\SYSTEM. As a result, any local user can create or alter server-side scripts within the webroot and then trigger them via HTTP requests, causing arbitrary code to execute with SYSTEM privileges.
INFO
Published Date :
2025-11-19T16:21:42.943Z
Last Modified :
2025-11-20T15:21:17.350Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2025-34333 vulnerability.
| Vendors | Products |
|---|---|
| Audiocodes |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-34333.